1

Information Security Risk Management Jobs in Massachusetts

Security Risk Management * Security Engineering * IT Governance, Risk, and Compliance (GRC) * Hands-on experience with: * Microsoft Purview (Required) * Microsoft Defender * SIEM platforms * Security ...

Showing results 41-60

Information Security Risk Management information

See Massachusetts salary details

$34

$63

$82

How much do information security risk management jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for information security risk management in Massachusetts is $63.84, according to ZipRecruiter salary data. Most workers in this role earn between $49.62 and $71.68 per hour, depending on experience, location, and employer.

What is information security risk management?

Information Security Risk Management is the process of identifying, assessing, and prioritizing risks to an organization's information assets and implementing measures to mitigate those risks. This field involves analyzing potential threats, vulnerabilities, and the impact of security breaches to ensure data protection and regulatory compliance. Professionals in this area develop policies, select security controls, and monitor systems to reduce the likelihood and consequences of cybersecurity incidents. Effective risk management helps organizations safeguard sensitive information and maintain trust with customers and stakeholders.

What are the key skills and qualifications needed to thrive in information security risk management?

To thrive in Information Security Risk Management, you need a deep understanding of cybersecurity principles, risk assessment methodologies, and relevant legal or regulatory requirements, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or CISM. Familiarity with risk management frameworks (e.g., ISO 27001, NIST), vulnerability assessment tools, and governance, risk, and compliance (GRC) systems is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills set top professionals apart in this field. These competencies are crucial for identifying, evaluating, and mitigating security risks, ensuring organizational resilience and regulatory compliance.

What are some common challenges faced by professionals in information security risk management, and how are they typically addressed?

Professionals in Information Security Risk Management often face challenges such as keeping up with constantly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with various regulations. These challenges are typically addressed through continuous learning, close collaboration with IT and business teams, and implementing robust risk assessment frameworks. Proactive communication and regular updates to security policies also help manage risks effectively while supporting organizational goals.

What is the difference between Information Security Risk Management vs Cybersecurity Analyst?

AspectInformation Security Risk ManagementCybersecurity Analyst
CertificationsISO 27001, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk assessments, complianceMonitoring security systems, incident response
Industry UsageRisk management, governance, compliance teamsSecurity operations centers, IT departments

While both roles focus on protecting information assets, Information Security Risk Management emphasizes identifying and mitigating risks through policies and assessments, whereas Cybersecurity Analysts focus on monitoring security systems and responding to threats. Both roles often collaborate but serve different functions within an organization's security framework.

Infographic showing various Information Security Risk Management job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $132,777 per year, or $63.8 per hour.

Senior Information Security Analyst

Chelmsford, MA

Full-time

Posted 4 days ago


Job description

Primary Responsibilities
  • Perform information security risk assessments, control evaluations, and security reviews.
  • Identify security risks, assess impact, and recommend mitigation strategies.
  • Review security controls and ensure alignment with enterprise security standards and policies.
  • Provide expertise on security frameworks, governance processes, and industry best practices.
  • Support security architecture reviews for applications, infrastructure, and technology initiatives.
  • Drive implementation and optimization of Microsoft Purview security and compliance solutions.
  • Support Microsoft Defender, SIEM tools, and security monitoring activities.
  • Assist with IT Governance, Risk, and Compliance (GRC) processes.
  • Collaborate with security, infrastructure, and application teams to improve security posture.
  • Maintain security documentation, assessment reports, control evidence, and remediation plans.
Required Qualifications
  • 6–9 years of experience in:
    • Information Security
    • Security Risk Management
    • Security Engineering
    • IT Governance, Risk, and Compliance (GRC)
  • Hands-on experience with:
    • Microsoft Purview (Required)
    • Microsoft Defender
    • SIEM platforms
    • Security monitoring and compliance solutions
  • Strong experience performing security risk assessments and control testing.
  • Knowledge of security frameworks, policies, and compliance standards.
  • Experience with security architecture reviews and technology risk assessments.
  • Strong analytical, communication, and documentation skills.
Preferred Qualifications
  • Experience with GRC platforms and security governance tools.
  • Knowledge of enterprise security frameworks such as NIST, ISO 27001, or similar standards.
  • Experience improving security processes and implementing security best practices.